“Personal Data” means: (a) any information that relates to, is linked to, or is capable of being linked to, an identified or identifiable individual; or (b) any information that is defined as “personally identifiable information,” “personal information,” “personal data,” or other similar terms by any Company Privacy Requirement or Purchaser Privacy Requirement.
“Privacy Laws” means (i) each applicable law, statute, order, rule, regulation, policy and/or guideline of any Governmental Entity regulating the protection or Processing or both of Personal Data, including, but not limited to, (A) the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and other comprehensive state data privacy laws, (B) the Telephone Consumer Protection Act and laws regulating direct marketing, e-mails, text messages, robocalls, telemarketing or other electronic communications, (C) the Computer Fraud and Abuse Act and analogous hacking or computer crime laws, (D) all laws governing notification of Security Breaches, and (E) to the extent applicable, laws and rules relating to the collection and Processing of biometric data and analogous terms, recording of telephonic or electronic communications (including wiretapping and/or eavesdropping) and (ii) industry self-regulatory principles or standards relating to the protection or Processing of Personal Data (including, if applicable, the Payment Card Industry Data Security Standards) that are binding on Company or Purchaser or to which Company or Purchaser expressly represents compliance.
“Process,” “Processed,” “Processes” or “Processing” means any operation or set of operations performed on Company Data or Purchaser Data, as the case may be, whether or not by automatic means, such as receipt, collection, monitoring, maintenance, creation, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, processing, analysis, transfer, transmission, disclosure, dissemination or otherwise making available, alignment or combination, blocking, erasure, destruction, privacy or security or any other operation that is considered “processing” or similar term under Company Privacy Requirements or Purchaser Privacy Requirements, as the case may be.
“Security Breach” means any (i) breach, unauthorized access, acquisition, interruption of access or other unauthorized Processing, loss, disclosure, theft, corruption of Company Data or Purchaser Data, as the case may be, (ii) inadvertent, unauthorized or unlawful sale or rental of Company Data or Purchaser Data, as the case may be, (iii) a phishing, ransomware, denial of service (DoS) or other cyberattack or (iv) other unauthorized breach, cyberattack access to, use of, or interruption of any Company IT Systems or Purchaser IT Systems, as the case may be, that compromises the confidentiality, integrity, availability or security of Company Data or Company IT Systems or Purchaser Data or Purchaser IT Systems, as the case may be.
(b) Company’s and its Subsidiaries’ data, privacy and security practices conform, and since January 1, 2022, have conformed, to all Company Privacy Requirements. Company and its Subsidiaries have provided legally adequate notice of its privacy and security practices in the Company Privacy Policies, and Company’s and its Subsidiaries’ privacy and security practices conform, and since January 1, 2022, have conformed, to all the now or then current applicable Company Privacy Policies. No disclosure made or contained in any Company Privacy Policy is, or at any time since January 1, 2022, has been, materially inaccurate, misleading or deceptive in a manner that has violated Company Privacy Requirements (including by containing any material omission).
(c) Company and its Subsidiaries have contractually obligated all third parties that have access to Company Data or Company IT Systems to comply with applicable Privacy Laws, and, to Company’s knowledge, no third parties with any such access have failed to comply with any such obligations.
(d) All Company IT Systems are configured in accordance with, and perform, and have for the past three (3) years performed, in material compliance with applicable industry security standards. The Company IT Systems are in good working condition and are sufficient in all material respects as is necessary for the businesses of Company and its Subsidiaries as currently conducted. Neither Company nor any of its Subsidiaries has experienced any material disruption to, or material interruption in, the conduct of its business attributable to a defect, error or other failure or deficiency of any Company IT System. Company and its Subsidiaries maintain reasonable and appropriate business continuity and disaster recovery plans relating to Company IT Systems, which are routinely tested with a frequency consistent with good industry and information security practices.